Centralized Logging for ECS Microservices: CloudWatch Logs Insights
A company has a microservices architecture with 50 services running on Amazon ECS. The DevOps team wants to collect and analyze logs from all services centrally. They need to query logs across services and set up alerts for error patterns. Which solution is the most scalable and cost-effective?
Quick Answer
The correct answer is to use the awslogs driver to send logs to Amazon CloudWatch Logs and then leverage CloudWatch Logs Insights for querying and metric filters for alerts. This solution is the most scalable and cost-effective for centralized logging for ECS microservices because the awslogs driver natively integrates with the ECS agent, automatically streaming container stdout and stderr to CloudWatch Logs without additional infrastructure. CloudWatch Logs Insights then provides a purpose-built query engine to search across all 50 services in seconds, while metric filters enable real-time alerting on error patterns without the latency of S3-based solutions. On the AWS Certified DevOps Engineer Professional DOP-C02 exam, this scenario tests your ability to balance operational simplicity with cost—common traps include choosing S3 with Athena (cheaper but lacks real-time alerts and has slower queries) or Elasticsearch (overly complex and expensive for this scale). Remember the memory tip: “Logs to CloudWatch, query with Insights, alert with filters—no extra servers required.”
⚠ Common exam trap
DOP-C02 often tests whether candidates default to self-managed Elasticsearch or S3+Athena for log analytics when the native, lower-overhead CloudWatch Logs solution is the intended answer — the trap is over-engineering.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use the awslogs driver to send logs to Amazon CloudWatch Logs and use CloudWatch Logs Insights for querying and metric filters for alerts
Using the awslogs driver to ship ECS container logs to Amazon CloudWatch Logs is the most scalable and cost-effective native solution. CloudWatch Logs Insights provides a query language for searching across log groups, and metric filters can trigger CloudWatch alarms on error patterns. This requires no cluster management, scales automatically with log volume, and integrates natively with ECS task definitions via the logConfiguration block.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use AWS CloudTrail to capture all log events and store them in an S3 bucket for analysis
Why it's wrong here
CloudTrail records AWS API activity, not application log output from ECS tasks, so it cannot supply the error patterns the team needs to query. CloudTrail is the right choice for auditing control-plane API calls and account activity, not for centralising container application logs.
- ✗
Deploy an Amazon Elasticsearch cluster and configure the ECS Fargate agent to send logs directly to Elasticsearch
Why it's wrong here
Configuring an ECS Fargate agent to send logs directly to an Amazon Elasticsearch cluster is not technically feasible. Fargate tasks do not expose an agent that can be configured for direct log forwarding; logs must be routed via a log driver (like `awslogs` to CloudWatch Logs) or a sidecar container running a log router such as Fluent Bit. However, Amazon OpenSearch Service (formerly Elasticsearch) is an excellent solution for centralising, querying, and alerting on logs, making it a strong choice if a proper log routing mechanism were in place.
- ✓
Use the awslogs driver to send logs to Amazon CloudWatch Logs and use CloudWatch Logs Insights for querying and metric filters for alerts
Why this is correct
The awslogs driver natively ships ECS container logs to CloudWatch Logs, where Logs Insights queries across all 50 services and metric filters trigger alerts on error patterns. This satisfies centralised querying and alerting without managing extra infrastructure.
- ✗
Send logs to Amazon S3 and use Amazon Athena for querying, with scheduled queries for alerts
Why it's wrong here
Athena queries S3 data only when queries run, and scheduled queries add latency, so real-time alerting on error patterns is not met. This pattern suits periodic batch analysis of archived logs, not continuous monitoring across 50 ECS services requiring immediate notification.
Go deeper
Related to this question
About these practice questions
Courseiva writes every DOP-C02 question from scratch — 1,298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on DOP-C02
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A company is running a production microservices architecture on Amazon ECS with Fargate. The operations team wants to set up centralized logging across all services, including the ability to search logs in near real-time and retain them for 3 years. The logs are currently sent to CloudWatch Logs. Which combination of services would meet these requirements with the least operational overhead?
hard- A.Stream logs to Amazon OpenSearch Service (Elasticsearch) using a CloudWatch Logs subscription filter.
- ✓ B.Set a retention policy of 3 years on the CloudWatch Logs log groups and use CloudWatch Logs Insights for searching.
- C.Export logs to Amazon S3 and use Amazon Athena to query them.
- D.Use Amazon Kinesis Data Firehose to deliver logs to Amazon S3 with a 3-year lifecycle policy.
Why B: Setting a 3-year retention policy on the CloudWatch Logs log groups and using CloudWatch Logs Insights for searching meets both requirements with the least operational overhead. CloudWatch Logs natively supports retention up to 10 years (3,653 days) and Insights provides near real-time querying without provisioning or managing additional infrastructure. This keeps everything within the existing logging pipeline.
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.